A new financial year is the natural time to sit down and reset your risk register. This one is different. FY26/27 brings a run of new Australian obligations that either start or get a lot stricter right around 1 July 2026. Mandatory climate reporting arrives for more businesses. Ransomware payment rules move into active enforcement. Psychosocial safety duties now apply in every state and territory. And the corporate regulator has been blunt that governance failures sit at the top of its enforcement list, not somewhere near the bottom.

For boards, compliance managers and operations leaders, that shifts the question you need to answer. It used to be “are we compliant on paper?” Now it is “can we actually show, with evidence, that we are managing these risks?” A certified management system is one of the clearest ways to prove it.

Here is what belongs on your FY26/27 agenda, why each item matters right now, and the practical steps to close the gap before it turns into an enforcement problem or a reputation one.

Why FY26/27 Is a Turning Point for Risk and Governance

Two things have moved the risk landscape up a gear.

First, regulators are acting, not just advising. The Australian Securities and Investments Commission (ASIC) has roughly doubled its new investigations and nearly doubled the number of new court proceedings it has started over the past year, and it has said that pace will keep up through 2026. Governance and directors’ duties failures remain one of its enduring priorities, and its own data shows a jump in misconduct reports driven by governance concerns. Directors who simply take management’s word for things, or who do not push back on weak controls, now face a genuine risk of personal accountability.

Second, the obligations themselves are becoming mandatory and tied to firm dates. Several land right on the FY26/27 line, so any business that treats 1 July as just another Tuesday will start the year behind. The organisations that come out ahead will be the ones that turned governance into a system that is documented, auditable and always improving, rather than a scramble once a year.

The rest of this article walks through the six priorities that deserve your attention this financial year.

Priority 1: Governance and Directors’ Duties Are a Live Risk

Governance is the umbrella that sits over everything else on this list. Through 2026, ASIC has said it will step up action on financial reporting misconduct and keep pursuing governance failures, market integrity breaches and systemic compliance failures.

For a board, the takeaway is simple. Oversight has to be evidenced. Receiving a management report is not enough. Directors are expected to question it, record that they questioned it, and be able to point to a clear trail of decisions and controls.

What to do in FY26/27. Think of your management systems as governance infrastructure. A certified quality management system (ISO 9001), or an integrated management system, gives directors a structured and independently audited way to show that risks are identified, controls are working, and problems get escalated and closed out. That trail is exactly the kind of evidence that separates a defensible board from an exposed one.

Priority 2: Mandatory Climate and Sustainability Reporting Begins

FY26/27 is the year sustainability reporting stops being optional for a much wider group of Australian organisations. Under the Australian Sustainability Reporting Standards, AASB S2 applies to Group 2 entities for annual reporting periods starting on or after 1 July 2026.

Group 2 covers entities that meet at least two of three thresholds on a consolidated basis: revenue of AUD $200 million or more, gross assets of AUD $500 million or more, or 250 or more employees. For most of them, the first sustainability report is due in late 2027, which means the data gathering and governance work has to happen this financial year.

One trap is worth calling out. Scope 3 emissions, the ones across your value chain, are not required in year one. But you need to start collecting that data straight away, because Scope 3 becomes mandatory from year two. Leaving it until the reporting deadline is not a real option.

What to do in FY26/27. Even businesses below the Group 2 thresholds will feel this, because larger customers will push emissions and sustainability questions down their supply chains. A certified environmental management system (ISO 14001) gives you the data, processes and governance to answer credibly, and it marks you as a lower-risk supplier the moment procurement teams start asking.

Priority 3: Cyber Security and Mandatory Ransomware Reporting

Cyber risk stopped being an IT problem and became a board-level legal obligation with the Cyber Security Act 2024. The important change for FY26/27 is the enforcement posture. The mandatory ransomware and cyber extortion payment reporting rules started on 30 May 2025 with an education-first phase. From 1 January 2026, the Department of Home Affairs shifted to active regulation.

Businesses with annual turnover above $3 million, along with critical infrastructure entities, must report any ransomware or extortion payment within 72 hours. There is no minimum payment threshold, so every payment counts, and failing to report on time can attract civil penalties.

What to do in FY26/27. Reporting after an incident is the floor, not the goal. The real aim is to stop the incident happening and to prove you did your due diligence if one does. A certified information security management system (ISO 27001) gives you an independently verified framework for managing that risk, and the Essential Eight gives you a practical maturity baseline. Together they show your board that cyber risk is being actively managed, not just insured against.

Priority 4: AI Governance Moves From Optional to Expected

Artificial intelligence is now woven through decision-making, customer service and daily operations in most organisations, and often with very little governance around accuracy, bias, security or accountability. As regulators and customers raise their expectations, “we use AI responsibly” is going to need proof rather than a promise.

What to do in FY26/27. Get ahead of it by formalising how AI is governed. ISO/IEC 42001, the international AI management system standard, gives you a structured way to manage AI risks around transparency, accountability and safety. For boards, moving early is both a control and a trust signal to customers and partners who are starting to ask harder questions about how you deploy AI.

Priority 5: Psychosocial Safety Is Now Enforceable Everywhere

Work health and safety duties have widened significantly. With Victoria’s standalone psychosocial regulations in force from December 2025, every Australian jurisdiction now requires employers to identify, assess and control psychosocial hazards. That covers bullying, excessive job demands, fatigue, harassment and poorly managed change. Safe Work Australia has confirmed psychological health stays a priority enforcement area.

This is a real board-level duty. As a Person Conducting a Business or Undertaking (PCBU), your organisation has a primary duty of care that reaches into psychological safety, and falling short can bring significant penalties and enforcement action.

What to do in FY26/27. Move from one-off wellbeing initiatives to a systematic approach. A certified occupational health and safety management system (ISO 45001), backed by the psychosocial risk guidance in ISO 45003, shows that you are taking reasonably practicable steps to protect psychological health in a structured and auditable way. That is the standard regulators now expect.

Priority 6: Privacy, Data and Sector Obligations

Two more areas round out the FY26/27 agenda. Privacy expectations keep climbing, and any organisation handling large volumes of personal data should strengthen its privacy governance. A certified privacy information management system such as ISO 27701 extends an existing ISO 27001 system to cover privacy risk directly.

Sector obligations are also tightening. NDIS providers, for example, are dealing with evolving registration and practice standard requirements, which makes solid NDIS certification and audit readiness an ongoing priority into FY26/27. The thread running through all of this is the same. Demonstrable, independently verified systems beat internal assurances every time.

Turning FY26/27 Priorities Into an Action Plan

The common thread across all six priorities is a move from intention to evidence. Regulators, customers and boards increasingly want proof that risks are being managed, and a certified management system is the most efficient way to produce that proof once and reuse it everywhere.

A practical FY26/27 sequence looks like this:

  1. Run a governance and risk gap analysis early in the year, mapping each obligation above to a current control, or to a gap.
  2. Prioritise by exposure. Cyber, psychosocial and, for larger entities, climate reporting carry the nearest term enforcement risk.
  3. Consolidate into an integrated management system instead of running separate, siloed programs, so one audit trail serves quality, safety, environment and information security.
  4. Certify with an accredited, independent body so the evidence carries weight with regulators, customers and your own board.

Getting this right does more than lower risk. It shortens sales cycles when procurement teams ask for certification, strengthens tender submissions, and lets leadership head into the year knowing FY27’s obligations are handled rather than hoped for.

Partner With GCC for FY26/27 and Beyond

Global Compliance Certification (GCC) is a leading independent certification body accredited by JASANZ. We help Australian organisations turn compliance obligations into a real business advantage across quality, safety, environment, information security, privacy, AI and NDIS.

If FY26/27 is the year you want to move from reactive compliance to demonstrable governance, we can help you map the right pathway.

Request a quote  or  contact the GCC team to plan your FY26/27 certification roadmap